Cybersecurity
CrowdStrike investigates FalconFlank privilege escalation report
An anonymous researcher called Nightmare Eclipse said FalconFlank could abuse CrowdStrike Falcon on current Windows systems, while CrowdStrike said it was investigating and told customers to change a policy setting.
- Nightmare Eclipse released FalconFlank and described it as a zero-day privilege-escalation exploit for CrowdStrike Falcon.
- The researcher said it affected current Windows 11 and Windows Server builds and could give an attacker SYSTEM access by abusing Falcon's handling of malicious Office macros.
- CrowdStrike said it was investigating the claims, advised customers to disable a Microsoft Office Windows policy setting for File Suspicious Macro Removal, and said customers still had protection through Cloud Anti-malware for Microsoft Office Files settings.
- Kevin Beaumont said the other privilege-escalation exploits Nightmare Eclipse released this week worked, and Nightmare Eclipse also disclosed zero-days for Kaspersky Antivirus for Endpoint, Avast Antivirus and Nvidia, plus several Microsoft products.
Nightmare Eclipse released FalconFlank and said it was a zero-day privilege-escalation exploit for CrowdStrike Falcon. The researcher said it worked on current Windows 11 25H2 and Windows Server 2025 systems and could let an attacker gain SYSTEM access by abusing Falcon's remediation feature for malicious Office macros.
When BleepingComputer asked CrowdStrike for more detail, a spokesperson said the company was investigating the claims. The spokesperson advised customers to disable the Microsoft Office Windows policy setting that controls File Suspicious Macro Removal, said customers still had protection through Cloud Anti-malware for Microsoft Office Files, and pointed readers to a FalconFlank tech alert that was only available through CrowdStrike's support portal.
This week Nightmare Eclipse also released privilege-escalation exploits for Kaspersky Antivirus for Endpoint and GenDigital's Avast Antivirus, together with a denial-of-service exploit for Nvidia called GreenSection. Kevin Beaumont said on Thursday that the privilege-escalation exploits released this week were real and worked.
Nightmare Eclipse had also disclosed several Microsoft zero-days since April, covering Microsoft Defender, BitLocker and other Windows components. Microsoft said after the first disclosures that it might take legal action against people involved in malicious activity that harmed customers, and some of the named flaws had since been fixed while others still awaited patches.
Named in this story
People
- Nightmare Eclipse
- the anonymous researcher who released FalconFlank and other exploits
- Kevin Beaumont
- the security expert who said the week's privilege-escalation exploits worked
Companies
- CrowdStrike
- said it was investigating the claims and advised customers on a setting change
- Microsoft
- the vendor that had multiple zero-days disclosed against its products and warned about legal action
- Nvidia
- the vendor whose systems were said to be hit by a crash bug
Products and systems
- FalconFlank
- the named zero-day privilege-escalation exploit
- CrowdStrike Falcon
- the endpoint security platform FalconFlank targeted
- Windows 11
- one of the Windows versions said to be affected
- Windows Server 2025
- one of the server versions said to be affected
- Kaspersky Antivirus for Endpoint
- one of the products targeted by Nightmare Eclipse
- HardBreacher
- the privilege-escalation exploit released for Kaspersky
- Avast Antivirus
- GenDigital's antivirus product targeted by another exploit
- PrettyPrague
- the privilege-escalation exploit released for Avast
- GreenSection
- the denial-of-service exploit released for Nvidia
- LegacyHive
- one of the Microsoft zero-days disclosed since April
- RoguePlanet
- one of the Microsoft zero-days disclosed since April
- YellowKey
- one of the Microsoft zero-days disclosed since April
- GreenPlasma
- one of the Microsoft zero-days disclosed since April
- MiniPlasma
- one of the Microsoft zero-days disclosed since April
- UnDefend
- one of the Microsoft zero-days disclosed since April
How the source tells it
The article read as brisk and threat-focused, with alarm from SYSTEM-level impact, urgency from active vendor response, and novelty from a run of newly named exploits.
- alarm the consequences were framed around SYSTEM-level access and a system crash
- novelty a cluster of newly named zero-days and exploit labels gave the piece a fresh-wave feel
- urgency live investigation and immediate mitigation advice were emphasised as the story unfolded